Azure Cloud NGFW provisioning state in Failed status due to missing SNAT IP

Azure Cloud NGFW provisioning state in Failed status due to missing SNAT IP

1978
Created On 12/03/24 19:34 PM - Last Modified 08/13/25 02:34 AM


Symptom


  • Azure Cloud NGFW Provisioning State failed.

Provisionig_State_Failed_Azure_CNGFW.png



Environment


  • Cloud NGFW
  • Supported PAN-OS
  • Azure Platform


Cause


  • Source NAT configured but source nat IPs not provide.
  • This can be seen under Cloud NGFW > Activity Logs
"statusMessage": "{\"status\":\"Failed\",\"error\":{\"code\":\"ResourceOperationFailure\",\"message\":\"The resource operation completed with terminal provisioning state 'Failed'.\",\"details\":[{\"code\":\"BadRequest\",\"message\":\"Firewall updation failed with message : , egress nat is enabled, but egress nat ips are not provided\"}]}}",

Azure_CNGFW_Activity_Log.png

Azure_CNGFW_Networking & NAT.png



Resolution


  1. When enabling Egress NAT or Source NAT, configure the NAT IPs.

Use_Source_NAT_IP.png



Additional Information


NA

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000TpNbCAK&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language